Release notes
Changelog
Site update, August 30, 2026 · Buy several apps in one order
- One payment, as many apps as you need. The commercial license window on this page could sell exactly one thing: Scrubbr. A team that also wanted two other twoplus11 apps paid three separate times, on three separate pages, and filed three separate receipts. That window now carries an Add another app control: search the catalog, set how many computers each app goes on, and pay once. Every app still gets its own license key, and they all arrive in the same email.
- Nothing changes if Scrubbr is all you want. The window opens exactly as it did, at the same price, with the same count of computers, and an order for a single app takes the route through checkout it always has. The extra controls appear only once the app list has loaded, so a slow or unreachable connection leaves the page as it was.
1.4.0 — August 22, 2026 · Proof, not a green tick
- New: Scrubbr now shows you what is still in the clean copy. It has always read the file back after writing it — that is how it knew how many fields came out — and it never showed you the other half of that reading. Every cleaned file now carries a Still in the clean copy section naming, field by field, exactly what a reader of that file can still see, with anything that gives something away flagged the same red as the reveal above it. Nothing left means it says nothing is left. This is the answer to the question the app exists to answer, and until now you had to take its word for it.
- New: a copy that came out unchanged no longer wears a tick reading “Cleaned”. Location only removes GPS and nothing else — which for a PDF, a Word document or an MP3 means removing nothing at all, because none of those formats has anywhere to put a location. Scrubbr wrote “Contract (scrubbed).pdf”, an exact byte-for-byte copy of the file that names its author, its title and its keywords, and reported it as a clean. That card now says Nothing was removed, in amber rather than green, and lists what the copy still carries.
- New: and it tells you which switch to flip. “Location only” is a setting that sticks — turned on once for a holiday photo, still on weeks later when a contract goes in. The card says so in as many words and names the control to change. For a format Scrubbr genuinely cannot rewrite, it says that instead, rather than implying you did something wrong.
- New: the copied report ends with the proof. The report you put on the clipboard before deleting a file now carries an After cleaning block: the name of the copy that was written and everything still in it, in the same layout as the reveal above. A receipt that stops at what a file used to carry proves nothing about the one you are actually sending.
- New: a batch says how many came out unchanged. “Cleaned 10 files” when nine were cleaned and one was passed straight through named the wrong number for the one file the batch was run for. And a batch where nothing at all worked now says how many failed instead of only that nothing happened.
- Fixed: “hidden fields removed” was a subtraction, not a count of what was removed. Scrubbr worked it out as how many fields there were minus how many there are now, which is only the right answer if nothing goes back in — and something does: the system’s own PDF writer stamps a fresh producer name and new dates into every PDF it saves. Seven fields out and three back in read as “4 hidden fields removed”; an even swap read as zero, so a clean that really happened reported nothing at all. It is now a count of the fields that are actually gone.
- Fixed: reading a photo’s ISO probed a macOS value in a way that is both slower than asking it directly and wrong for one kind of value — a run of raw bytes would have been printed as a list of numbers.
1.3.0 — August 22, 2026 · Everything the file is carrying, not the third we had an opinion about
- New: Scrubbr shows you all of it now. It only ever surfaced the metadata it had a privacy opinion about — your location, your name, your camera — plus a short list of plain facts like the pixel size. Everything else your file was carrying was read, understood and thrown away without a word. A photo from a modern phone holds around ninety pieces of metadata; Scrubbr had a row for thirty. Every file now has an All metadata section listing every last one, under the names the format itself uses, folded away until you ask for it so the reveal is still the first thing you see.
- New: things nothing was telling you about. Among the sixty a photo was hiding: the exact second your GPS fix was taken, how accurate it was and which map datum it used, your time-zone offset — which is roughly your longitude — the metering mode, exposure program and white balance, and, in files that have been through a photo editor, the headline, category, urgency and any “do not syndicate”-style instruction left in them. Music files give up unmapped tags along with the album and year sitting in the old-style tag at the end, where before there was one row saying a legacy tag was present. Video files show every QuickTime atom, including ones Scrubbr previously listed as nothing at all. And a file Scrubbr cannot open shows every macOS attribute stapled to it, not just the five it strips.
- New: the copied report matches what you saw. A single file’s report now carries the complete list too, so the evidence you keep before cleaning is the same evidence the app showed you. A whole-batch report stays a summary — hundreds of files times ninety keys is not something anyone can read, let alone paste into a ticket.
- Fixed: a name that was a name, shown as if Scrubbr had failed to read it. Anything a file stored as a list — the photographer’s name in a photo edited in Lightroom or Photoshop, its keywords, a PDF’s keyword list — reached the screen as
(↩ Jeremy↩)instead ofJeremy. That was Scrubbr printing a raw macOS structure rather than reading it. Lists now read as lists:cat, summer. - Fixed: video timestamps reported as a file size. The tags a camera writes into a QuickTime or MP4 file arrived with their names garbled into escape codes (
%A9TIMrather than©TIM), and the readable text inside them was reported as “15 B” — the number of bytes in a value that was sitting right there in plain text. - Fixed: dismissing the license window could destroy a paid key. Pressing Escape on the activation window ran the same code path as Remove license — so a customer whose key failed to validate for a moment (a server hiccup, no connection, a seat limit) and then closed the window lost their only copy of it, with no confirmation and nothing saying it had happened. Dismissing now simply closes the window; dropping to personal use is still the explicit Remove button’s job, and that one asks first.
- Fixed: Scrubbr was breaking its own Apple signature to change its icon. Following the system between light and dark appearance, it wrote a Finder icon inside its own application bundle — which invalidates the Developer ID signature on your Mac at first launch, and can stop the app accepting its own updates. Both icons now ship inside the app and the Dock tile is repainted in memory, touching nothing on disk.
- Unchanged on purpose: the numbers still count only hidden metadata. The red warnings, the “3 sensitive” badge, the count in the toolbar and what a clean reports removing all still count the metadata that gives something away. A photo that admits it is 72 dpi has not become a photo that leaks your address, and nothing in the new section is allowed to inflate a number Scrubbr puts its name to.
1.2.0 — August 20, 2026 · The button says when it replaces, and a clean you can stop
- New: Scrubbr shows you where a file came from. Every file you download on a Mac quietly carries the web address it came from — including the one-off link with your order number or login token in it — along with the app that downloaded it and any Finder comment or tag. macOS staples those to the outside of the file rather than putting them inside it, which is why they survive almost every other metadata remover. Scrubbr lists them with the rest, flags the web address in red, and no clean copy carries them.
- New: that works even on files Scrubbr can’t open. A ZIP, an installer, a spreadsheet in a format Scrubbr has no reader for — drop one in and you still get the reveal, and still get a clean copy.
- New: Scrubbr tells you when a file carries Content Credentials. Some cameras and AI tools attach a signed record of what made a file and how it was edited. Scrubbr says when one is there, says plainly that it finds the record rather than checking the signature on it, and warns up front that cleaning an image destroys it.
- New: copy the report before you strip it. One click puts a plain-text list of everything a file was carrying on the clipboard — one file or the whole batch — laid out the way the app shows it, with the revealing sections marked.
- New: sort and filter the list. Order the loaded files by name, size, kind or how much they reveal, click again to reverse, once more to go back to the order you added them — and switch on a filter that hides everything not carrying something sensitive.
- Changed: “Replace all 40” now says so. Replace original is a setting that sticks — switch it on once and every launch after that opens with it armed. It asked before arming and then never mentioned itself again, so a later session’s Scrub all could overwrite forty originals while reading exactly like the button that writes forty clean copies. The button now says Replace when it will replace, counts what it will replace, and tells a screen reader that a backup is kept of each.
- Fixed: the help sheet and the empty state tell the truth about the mode you’re in. Both promised, flatly and unconditionally, that your source file is never changed or deleted — which is exactly what Replace mode does not do. They now describe whichever mode is actually switched on.
- New: a batch clean can be stopped. Dropping a folder can queue thousands of files, and cleaning writes to disk; there was a progress bar and no way out but force-quitting. Stop finishes the file it is on, so nothing is ever half-written, and Scrubbr reports how many it left untouched rather than only what it managed.
- New: a file that failed to clean can be tried again, from its own button on the card — no more removing the file and adding it back to retry after fixing a permissions problem. And every file can now be removed with the mouse, not just from the keyboard.
- New: files say which folder they came from. Dropping a folder pulls in everything inside it, so a list could show a wall of cards all reading
IMG_4021.jpgthat were different files in different subfolders. Each card now carries its folder — just the part that differs — and only when the batch actually spans more than one. Remove all files can also be undone. - Fixed: the list sorted in the wrong order. Names were ordered the way Unicode stores letters rather than the way people read them, so
Éditeur.jpgandÜbertragung.pdffiled afterZoom.png, andIMG_10.jpgcame beforeIMG_2.jpg. Names now collate properly in all thirteen languages and a burst of photos reads in counting order — including the order a dropped folder is added in, which is what the copied report is written in. - Fixed: a failed scrub could leave a stray copy behind. Replacing an original saves a “(original)” backup first, then swaps the clean file in. If the swap failed, that backup was left sitting in your folder with nothing on screen explaining the extra file. It is now cleaned up when the swap never happened.
- Fixed: several screen-reader gaps — a failure reported over a sheet or dialog was painted behind it, an error could be wiped by the next success before it was read out, and a scrub where every file failed sounded exactly like one where every file worked.
- Fixed on this website: the Buy button in the mobile menu, the skip to content link on the privacy, terms and changelog pages, and both buttons in the purchase panel drew white text on a fill too light to read it — as low as 2.5:1 where the accessibility guidelines ask for 4.5:1. All five now clear that bar. The home-screen icon and the link preview image were also still the old purple artwork from before the icon was redrawn; both now match the app.
- A file with nothing to hide now has something to show. Scrubbr only ever listed the metadata it had a privacy opinion about, so a photo you had already cleaned — or one that never carried anything in the first place — opened onto a card whose entire content was a sentence saying there was nothing to see. Open one now and there is an Also in this file section under the reveal: how many pixels wide the photo is and what color profile it uses, the shutter speed, aperture, ISO and focal length the shot was taken at, how many pages and what size they are in a PDF, the page, word and slide counts in an Office document, the codec, duration and bitrate of a video, and what an MP3’s audio actually is even after every tag has been stripped off it. A file Scrubbr has no reader for at least says what kind of file it is.
- None of it is treated as a leak. The new section is deliberately kept apart from the metadata above it: nothing in it is counted as hidden, nothing in it is counted as removed, nothing in it is red, and the sensitive count and the summary mean exactly what they meant before. It is there to be interesting, not alarming.
- Copy report includes it. The plain-text report you can put on the clipboard now carries the same section, under the same heading, in all thirteen languages.
- The company name on an activated business license was always blank. Scrubbr read it from a field the licensing server stopped sending — the name is there, and it now appears. Nothing about how licenses work changed; only what the window could see.
Site update — August 19, 2026 · A checksum for the download
Website only; no change to the app.
- The download page now publishes the SHA-256 of the
Scrubbr.dmgit serves, so you can confirm the file you got is the file we put there. macOS already runs the check that matters — Scrubbr is signed with an Apple Developer ID and notarized by Apple, and a copy altered after we signed it will not open — but there was no way to check a download by hand, which is what anyone installing it on more than their own Mac tends to want. The checksum is on the download section under SHA-256 checksum, next to the one command that compares it with your copy. It is published as a plain file too, atScrubbr.dmg.sha256, in the formatshasum -creads.
Site update — August 17, 2026 · The other apps, after the sign-up
Website only; no change to the app.
- The list of the other twoplus11 Mac apps has moved to the bottom of the page, below the email sign-up rather than above it. It used to arrive while the page was still making its case for Scrubbr, so the last thing you read before being asked for your email was a wall of other apps. It sits at the end now — the page finishes on Scrubbr, and the list is there if you want to see what else there is.
Site update — August 14, 2026 · Headlines in one color
Website only; no change to the app.
- The headline no longer fades from one color into another across the letters. A gradient poured through text is the house style of every generated landing page on the web, and it was on the hero here, on the small uppercase label above each section, and on the license label in the purchase panel. The words are one solid color now — the accent this page already used everywhere else — so the headline finally matches the page under it.
- The figures on the download-stats page were faded the same way and are plain white now. The color belongs to the bars beside them, not to the digits.
- Gradients are kept where they belong — the buttons, the app tile and the rule above the support panel are untouched. It is only text that stopped fading.
- No change to the app.
Download update — August 12, 2026 · Opens without an internet check
- The copy of Scrubbr in the download now opens without needing the internet. macOS checks that an app has been approved by Apple before it runs for the first time. That approval can travel inside the app itself, and in the download it did not — so the first launch had to reach Apple to confirm it. Offline, behind a hotel or campus login page, or when Apple’s service was slow, that check could fail and macOS would report that Scrubbr “cannot be opened because Apple cannot check it for malicious software.” The approval now travels with the app, so the first launch works with no connection at all.
- Automatic updates were never affected — the copy they install already carried its approval.
- The installer window opens at the right size. It was one title bar too short, so the artwork behind the drag-to-Applications arrow was cut off along the bottom and the window opened already scrolled. It now fits exactly.
- The app itself is unchanged: same version, same signature. Only the download was repackaged, so there is nothing to do if you already have Scrubbr installed.
Site update — August 12, 2026 · How updating really works
- The update instructions were out of date. They described downloading a new copy and dragging it over the old one. Scrubbr updates itself — it checks about once a week and offers to install the new version in place, refusing any download that isn't signed by us. You can still replace it by hand, and you can turn the automatic check off.
- Nothing else changed. What this page already said about your files — that they are never uploaded, and that there is no account and no telemetry — was accurate and is unchanged.
- No change to the app.
Site update — August 12, 2026 · Readable buttons and small print
- The buttons in the header say what they say. The Tip and Download pills were drawing their label at 55% opacity over a colored fill, which measured as low as 1.6:1 against it — well under the 4.5:1 the accessibility guidelines ask for. Their labels are now solid, and the fill behind them is set a shade deeper so the text genuinely clears that bar.
- The Subscribe and Support buttons too. Their labels were colored for one end of a two-color gradient and disappeared into the other end. Both now use a single fill that the label is legible on all the way across.
- The newsletter note, the “More apps” caption and the version line under the download button were all set too faint to read comfortably; each is now above the AA threshold.
- Keyboard shortcut chips are legible against their own background.
- No change to the app.
Site update — August 11, 2026 · Clearer search results
- The description under this site in Google is no longer cut off. It ran past the length Google shows and broke mid-word; it now reads as a complete sentence.
- The page title was also long enough to be truncated in search results, and has been shortened to fit.
- Sharing a link to the privacy, terms or changelog page now shows a proper preview card instead of a bare URL.
- The sitemap now reports when each page actually changed, so search engines re-check pages that have been updated instead of assuming they are stale.
- No change to the app.
August 11, 2026 · A new look
- Changed: Scrubbr has a new app icon. Every twoplus11 app moved to one generated palette, so the color in your Dock, on this site and on the download page is now the same color — they had drifted apart.
- Changed: refreshed the site to match, including the tab icon and the link preview image.
Site update — August 10, 2026 · Real screenshots of the app
- The product page illustrated the app with a hand-drawn mock-up of a window rather than showing Scrubbr itself. It now shows the running app: the hidden location, identity and device fields a sample photo was carrying, and a short animation of stripping them into a clean copy. No change to the app.
1.1.11 — August 9, 2026 · Automatic updates
- New: Scrubbr updates itself. When a new version is out you get a prompt with the release notes and can install it in place — no more visiting the site and dragging a new copy over the old one. This is the last update you have to install by hand.
- New: refreshed appearance — Scrubbr now uses the shared twoplus11 palette and a regenerated app icon, so it matches the rest of the family.
- Fixed: contrast and keyboard-navigation problems (WCAG 2.1 AA) — faint text is now readable, and every control can be reached and used from the keyboard.
- Fixed: the Check for Updates button spins while it checks, instead of flashing an empty window.
1.1.10 — July 20, 2026 · Icon refinement
- Refined the app icon: two clean plus-mark sparkles and a crisp eraser, tuned to stay legible all the way down to Dock and favicon size.
- The in-app icon, the Dock icon, and the website icon are now generated from a single source, so they always match.
1.1.9 — July 17, 2026 · Icon refresh
- Refined the app icon: the sparkle trail is now three fading stars instead of plus-marks, and a stray line in the shine has been cleaned up.
1.1.8 — July 17, 2026 · 13 languages
- New: 13-language localization with an in-app flag picker (auto-detects your Mac's language, override anytime).
- Fixed: "Location only" mode now actually keeps non-GPS metadata (Author/Company/Artist, etc.) — previously it was removed the same as "Everything" mode.
1.1.7 — July 16, 2026 · Appearance override fix
- Fixed: pinning the appearance to Light or Dark (instead of following the system) now restyles the whole window — previously the translucent header and footer kept the system's appearance, leaving hard-to-read text when the override and the system disagreed.
1.1.6 — July 15, 2026 · “Tip”
- Renamed the “Donate” link to “Tip.”
1.1.5 — July 15, 2026
- Refined the dark-mode Dock icon: now a true near-black, monochrome-style background with just a hint of purple, instead of a deeper tint of the same color.
1.1.4 — July 15, 2026
- Fixed: the app icon could show the wrong light/dark variant in Finder, Spotlight, Launchpad, and the Dock while Scrubbr wasn't running. It now updates everywhere immediately, not just the Dock tile of an already-open app.
1.1.3 — July 14, 2026
- New: the Dock icon now follows your Mac's light/dark appearance automatically — or pin it to Light or Dark from the new appearance toggle.
- Fixed: the Dock icon rendered edge-to-edge with no padding, making it look larger than every other app in the Dock. It now follows Apple's standard icon grid, sized and spaced to match.
1.1.2 — July 13, 2026
- twoplus11 wordmark credit in the footer and update panel.
- Occasional, low-pressure prompt to support twoplus11 after extended use — never more than once, easy to dismiss for good.
1.1.1 — July 12, 2026
- New: clearer Help and Review buttons in the header, so support and feedback are one click away.
- Fixed: re-scanning a folder no longer skips a file just because its name happens to contain "(scrubbed)" — that guard now only applies to Scrubbr's own scrubbed copies, not files you drop or pick directly.
1.1.0 — July 11, 2026 · Deeper reveal, more thorough strip
A deep polish and capability pass. The reveal got more powerful, the strip got more thorough, and everything got faster and friendlier.
- Audio really scrubs now. Dropping an MP3 or AAC strips its ID3v2 (and legacy ID3v1) tags with a pure-stdlib rewriter — artist, "encoded by," encoder software, comments, embedded private frames and timestamps all go, and the audio bytes are preserved exactly (no re-encode). Previously inspect-only.
- Office comments & tracked changes are actually removed. With the option on, Scrubbr now deletes the comment parts and their relationships, content-type overrides and in-body anchors, and accepts every tracked change (keeps inserted text, drops deleted text, strips the revision markup) — leaving clean, valid OOXML. Formatting and tables are preserved.
- PDF wart minimized. PDFKit re-stamps a generic Producer and fresh dates on every save; Scrubbr now blanks those (and any reachable XMP) in place, byte-for-byte, so a re-inspect comes up empty — and it's honest in the UI about what a PDF writer can't reach.
- Folder & bulk drops. Dropping a folder now recurses into it and adds every supported file; drop many at once. A progress bar shows the scan and big batch scrubs, and there's a per-file thumbnail/preview.
- Privacy summary headline. A banner up top tells you the scary truth at a glance — "3 of 7 files reveal your location" — with a one-click Scrub.
- Select & scrub the ones you want. Checkbox-select files (keyboard-friendly) and Scrub selected, or Scrub all.
- Reveal in Finder for the original, not just the clean copy.
- Replace original (keep backup). Opt-in in-place scrub that overwrites the file and keeps a "(original)" backup beside it — never lossy, off by default. If a source folder is read-only, Scrubbr offers to save the clean copy in a folder you pick instead of failing.
- Remembered options. Your last-used strip settings persist across launches.
- Friendlier everywhere. Recoverable, plain-English messages for read-only folders, full disks, permission issues and unreadable files — never a raw traceback. Progress announcements and the privacy summary are surfaced to VoiceOver.
1.0.0 — July 11, 2026 · Initial public release
The first release. Drop a file, see what it's hiding, strip it — with your original never touched.
- The reveal. Drop a photo, PDF, Office document or video and Scrubbr shows the hidden metadata it's carrying — GPS location, author, camera make/model and serial, software, tracked changes, comments, timestamps — grouped into Location, Identity, Device, History, Timestamps and Other, with everything privacy-relevant flagged red and explained in plain English ("reveals where this file has been").
- The strip. One click writes a clean copy next to the original — the source file is never overwritten or deleted, and if the "(scrubbed)" name is taken it disambiguates instead of clobbering.
- Images (JPG/PNG/HEIC/TIFF/GIF): pixels re-encoded to a fresh file with no EXIF/GPS/XMP; ICC color profile kept and orientation baked in so it looks identical.
- PDF: document info dictionary and XMP cleared (info dictionary only — not embedded object streams; the UI says so).
- Office (DOCX/XLSX/PPTX): authorship blanked, custom.xml dropped, comments and tracked-change parts optionally removed; zip order and compression kept.
- Video/audio (MP4/MOV/M4V/M4A): passthrough remux with metadata cleared — fast and lossless. The QuickTime GPS tag (the big iPhone location leak) goes with it.
- Options. Strip Everything or Location only; toggle Remove comments & tracked changes and Keep color profile.
- Batch. Drop many files (or a folder); each gets its own card; Scrub all cleans them in one go with a before → after summary and a Reveal in Finder link on each clean copy.
- 100% local. No file — or metadata — ever leaves your Mac.
- Bespoke, accessible UI. Native macOS look, light and dark mode, full keyboard navigation, focus-trapped modals, ARIA labels and live announcements, honoured Reduce Motion, helpful empty state, toast on every action, and a confirm modal for clearing the list.
- Free for personal use forever (including updates); one-time $5 business license.